Malicious
Malicious

PE Executable
MD5: cc729b30c34c7e3573b8b71b99fb72b0
Size: 307.71 KB
application/x-dosexec
Ctrl + scroll to zoom · drag to pan

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Low
MD5 cc729b30c34c7e3573b8b71b99fb72b0
Sha1 35aed0a1ed99a57c637aa75c61a50bab12723ef8
Sha256 31b81ea20ff83ca54ec0d7091722edf40cb2066170e1e7208b0cdb30a4a11d3c
Sha384 c9ff3a1c7fe01ca6b5e844fb7b39d79c596638137c2f4e9479b96831ebf2f1859d2d79a28b566d2ab89c67721dc2ce4e
Sha512 9ed6742bc30723db0dc745101de68061cb0279c47fa2fc87832d096fef4b3e848eec7ac9ab56456710ca182ef0d78c66145e37f6d07229b71e401c2d1d1cf196
SSDeep 3072:CcZqf7D34Op/0+mAmkyYZSQwguKB1fA0PuTVAtkxzn3RUeqiOL2bBOA:CcZqf7DI2nVRhB1fA0GTV8kBcL
TLSH 28645A5833E8C910DA7F4775D861D67093B0BCA3A556E70B4FC4ACAB3D32740EA50AB6
PeID
.NET executableMicrosoft Visual C# / Basic .NETMicrosoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL Microsoft Visual C# v7.0 / Basic .NETMicrosoft Visual Studio .NET
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_ICON
ID:0001
ID:0
ID:0-preview.png
ID:0002
ID:0
ID:0003
ID:0
ID:0004
ID:0
ID:0005
ID:0
ID:0006
ID:0
RT_GROUP_CURSOR4
ID:7F00
ID:0
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
Form1.resources
Patterns.Properties.Resource1.resources
rootCert
Config. Field Value
[Configuration Module Name] Arghuhuhuhu
[Configuration Module Full Name] Arghuhuhuhu
IP OTE6Rzhuhuhuhuhuhuhu
ID ECIlhuhuhuhu
Message
Key thuhuhuhu
Version 0huhuhuhu
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
Config. Field Value
[Configuration Module Name] Arghuhuhuhu
[Configuration Module Full Name] Arghuhuhuhu
IP (C2) 127.huhuhuhu
ID thuhuhuhu
Key thuhuhuhu
Version 0huhuhuhu
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
Name Value
Info
PE Detect: PeReader OK (file layout)
Module Name
Steanings.exe
Full Name
Steanings.exe
EntryPoint
System.Void Program::Main()
Scope Name
Steanings.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
Steanings
Assembly Version
1.1.21.1
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.0
Total Strings
301
Main Method
System.Void Program::Main()
Main IL Instruction Count
17
Main IL
nop <null>
nop <null>
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
nop <null>
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
nop <null>
newobj System.Void Form1::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
nop <null>
nop <null>
leave.s IL_0022: ret
stloc.0 <null>
nop <null>
nop <null>
leave.s IL_0022: ret
ret <null>
Module Name
Steanings.exe
Full Name
Steanings.exe
EntryPoint
System.Void Program::Main()
Scope Name
Steanings.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
Steanings
Assembly Version
1.1.21.1
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.0
Total Strings
301
Main Method
System.Void Program::Main()
Main IL Instruction Count
17
Main IL
nop <null>
nop <null>
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
nop <null>
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
nop <null>
newobj System.Void Form1::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
nop <null>
nop <null>
leave.s IL_0022: ret
stloc.0 <null>
nop <null>
nop <null>
leave.s IL_0022: ret
ret <null>
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_ICON
ID:0001
ID:0
ID:0-preview.png
ID:0002
ID:0
ID:0003
ID:0
ID:0004
ID:0
ID:0005
ID:0
ID:0006
ID:0
RT_GROUP_CURSOR4
ID:7F00
ID:0
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
.Net Resources
Form1.resources
Patterns.Properties.Resource1.resources
rootCert
Config. Field Value
[Configuration Module Name] Arghuhuhuhu
[Configuration Module Full Name] Arghuhuhuhu
IP OTE6Rzhuhuhuhuhuhuhu
ID ECIlhuhuhuhu
Message
Key thuhuhuhu
Version 0huhuhuhu
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
Config. Field Value
[Configuration Module Name] Arghuhuhuhu
[Configuration Module Full Name] Arghuhuhuhu
IP (C2) 127.huhuhuhu
ID thuhuhuhu
Key thuhuhuhu
Version 0huhuhuhu
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙